针对无线设备指纹识别的对抗攻击,实测成功率超80%。
Adversarial Attacks Against Deep Learning-Based Radio Frequency Fingerprint Identification
- 用FGSM、PGD、UAP三种方法生成干扰信号
- 对CNN/LSTM/GRU模型攻击成功率达81.7%
- 适合研究无线安全与对抗样本的学者
射频指纹识别(RFFI)是一种用于轻量级认证物联网设备的新兴技术,利用深度学习模型提取硬件缺陷以唯一标识无线设备。近期研究表明,基于深度学习的RFFI易受对抗攻击。然而,针对不同RFFI分类器的有效攻击尚未充分探索。本文系统评估了多种对抗攻击方法在使用不同深度学习模型的RFFI系统上的表现,分析了快速梯度符号法(FGSM)、投影梯度下降(PGD)和通用对抗扰动(UAP)三种算法。实验针对LoRa-RFFI系统进行,结果表明生成的扰动对卷积神经网络(CNN)、长短期记忆网络(LSTM)和门控循环单元(GRU)均有效。进一步采用UAP实施实际攻击,考虑无线环境特性,包括实时性、持续有效性等。实验评估显示,即使攻击者几乎无先验知识,UAP仍可成功攻击RFFI系统,成功率高达81.7%。
原文摘要 · Abstract (English)
Radio frequency fingerprint identification (RFFI) is an emerging technique for the lightweight authentication of wireless Internet of things (IoT) devices. RFFI exploits deep learning models to extract hardware impairments to uniquely identify wireless devices. Recent studies show deep learning-based RFFI is vulnerable to adversarial attacks. However, effective adversarial attacks against different types of RFFI classifiers have not yet been explored. In this paper, we carried out a comprehensive investigations into different adversarial attack methods on RFFI systems using various deep learning models. Three specific algorithms, fast gradient sign method (FGSM), projected gradient descent (PGD), and universal adversarial perturbation (UAP), were analyzed. The attacks were launched to LoRa-RFFI and the experimental results showed the generated perturbations were effective against convolutional neural networks (CNNs), long short-term memory (LSTM) networks, and gated recurrent units (GRU). We further used UAP to launch practical attacks. Special factors were considered for the wireless context, including implementing real-time attacks, the effectiveness of the attacks over a period of time, etc. Our experimental evaluation demonstrated that UAP can successfully launch adversarial attacks against the RFFI, achieving a success rate of 81.7% when the adversary almost has no prior knowledge of the victim RFFI systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。